HEALTH SERVICES LIMITED COMPANY (“ESLOTUS”) will be referred to as such hereinafter.) Within the scope of the Law on the Protection of Personal Data No. 6698 ("Law") and related legislation, your personal data may be processed by ESLOTUS in the capacity of Data Controller, within the framework outlined below, and in accordance with the Basic Law on Health Services No. 3359, the Decree Law No. 663 on the Organization and Duties of the Ministry of Health and its Affiliates, the Regulation on Private Hospitals, the regulations of the Ministry of Health, and other relevant legislation.
1. Collection, Processing, and Purposes of Processing Personal Data
Your personal data is collected by ESLOTUS through verbal, written, visual, or electronic means, such as call centers, websites, verbal or written channels, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment, and care services, and planning and managing health services and financing. Your sensitive personal data, particularly health data, and your general personal data may be processed by our clinics in connection with the purposes stated in this section, in a limited and proportionate manner, including but not limited to the following:
- Identity Information: Your name, surname, Turkish ID number, passport number or temporary Turkish ID number, place and date of birth, marital status, gender, insurance or patient protocol number, and other identity data that can identify you.
- Contact Information: Your address, phone number, email address, and other contact details; call recordings kept as per call center standards; and personal data obtained when you contact us via email, letter, or other means.
- Accounting Information: Your bank account number, IBAN number, credit card information, billing details, and other financial data.
- Data related to your private health insurance and Social Security Institution, for the purpose of financing and planning healthcare services.
- Images recorded by security cameras for monitoring and security purposes when visiting our clinics.
- Your vehicle license plate number if you use our parking area.
- Health Data: All health and sexual life-related personal data obtained during or as a result of medical diagnosis, treatment, and care services, including laboratory results, test results, examination data, appointment information, check-up data, and prescription details.
- Health and other personal data you submit or enter via the website www.eslotusclinics.com.
- If you apply for a job at any of our clinics, all your personal data including your resume; if you are an employee or affiliated staff member, all data related to your employment contract and suitability for work.
All personal data obtained by ESLOTUS (including, but not limited to, sensitive personal data) may be processed for the following purposes:
- To verify your identity.
- To protect public health, provide preventive healthcare, conduct medical diagnosis, treatment, and care services, and plan and manage health services and their financing.
- To share requested information with the Ministry of Health and other public institutions and organizations as per relevant legislation.
- To plan and manage the internal operations and daily processes of our clinic.
- To measure, improve, and investigate patient satisfaction through the Clinic Management, Patient Rights, and Patient Experience departments.
- To provide medication.
- To notify you about your appointments, if any.
- To perform risk management and quality improvement activities.
- To analyze in order to improve healthcare services.
- To finance your healthcare services, cover the costs of examination, diagnosis, and treatment, and share requested information with private insurance companies within the scope of eligibility checks, by the Patient Services, Financial Affairs, and Marketing departments.
- To conduct research.
- To fulfill legal and regulatory obligations.
- To share requested information with private insurance companies within the scope of healthcare financing.
- To perform risk management and quality improvement activities by the Quality, Patient Experience, and Information Systems departments.
- To issue invoices in exchange for our services and confirm your affiliation with contracted institutions by the Patient Services, Financial Affairs, and Marketing departments.
- To provide participation in campaigns and campaign-related information, and to design and deliver personalized content and tangible/intangible benefits on web and mobile channels by the Marketing, Media & Communication, and Call Center departments.
Your Personal Data obtained and processed in accordance with the relevant legislation may be transferred to the physical archives and/or information systems of ESLOTUS company and may be stored both digitally and physically.
2. Transfer of Personal Data
Your personal data may be shared, within the scope of the Law and other relevant legislation and for the purposes stated above, with the companies within ESLOTUS, private insurance companies, the Ministry of Health and its affiliated units, the Social Security Institution, the General Directorate of Security and other law enforcement agencies, the Directorate General of Civil Registration and Nationality, the Turkish Pharmacists' Association, courts and all kinds of judicial authorities, central and other third parties, your authorized representatives, lawyers, tax and financial advisors and auditors including third-party consultants we receive services from, regulatory and supervisory institutions, official authorities, business partners and other third parties with whom we cooperate to improve or carry out health services for the aforementioned purposes.
3. Method and Legal Basis for Obtaining Personal Data
Your personal data is collected and processed in any verbal, written, visual or electronic environment for the purposes stated above and in order to legally carry out any business related to the field of activity of ESLOTUS company and to fully and properly fulfill its contractual and legal obligations. The legal basis for collecting your personal data is;
- Law No. 6698 on the Protection of Personal Data,
- Law No. 3359 on Basic Health Services,
- Decree Law No. 663 on the Organization and Duties of the Ministry of Health and Its Affiliated Institutions,
- Regulation on Private Hospitals,
- Regulation on the Processing and Protection of Privacy of Personal Health Data,
- Regulations of the Ministry of Health and other provisions of the legislation.
In addition, as stated in paragraph 3 of Article 6 of the Law, personal data relating to health and sexual life may be processed without the explicit consent of the data subject by persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, as well as planning and managing health services and financing.
4. Your Rights Regarding the Protection of Personal Data
Pursuant to the Law and relevant regulations, you have the right to:
- Learn whether personal data is processed,
- Request information if personal data has been processed,
- Access and request your personal health data,
- Learn the purpose of processing personal data and whether they are used in accordance with the purpose,
- Know the third parties to whom personal data are transferred domestically or abroad,
- Request correction of personal data if it is incomplete or incorrectly processed,
- Request deletion or destruction of personal data,
- Request that transactions made regarding the correction and/or deletion or destruction of personal data be notified to third parties to whom personal data has been transferred,
- Object to a result arising against you by analyzing the processed data exclusively through automated systems.
If you use one or more of the above rights, the relevant information will be provided to you clearly and understandably in writing or electronically via the contact information you provide.
5. Data Security
ESLOTUS protects your personal data with full compliance with all technical and administrative security controls required by information security standards and procedures. These security measures are provided at a level appropriate to possible risks, considering technological capabilities.
6. Complaints and Contact
Your personal data is carefully protected within the bounds of technical and administrative capabilities, and necessary security measures are implemented at a level appropriate to possible risks, taking into account technological capabilities. We kindly ask you to send your requests within the scope of the Law to [email protected].